mirror of
https://github.com/stablyai/orca.git
synced 2026-09-22 08:02:28 +00:00
Flip `anti-slop/no-shape-in-symbol-names` from "off" to "error" and clear
every violation under src, config, tests and mobile.
What the rule bans
------------------
The case-insensitive substring "shape" in any JS/TS identifier: variables,
functions, parameters, types, type parameters, class members, private names,
object-literal keys and JSX identifiers. The one exemption is a statically
accessed member read owned by another value (`zodObject.shape` is fine), so
third-party APIs stay readable without a suppression.
"Shape" names a value's structure rather than its domain role. `UserShape`,
`validateArgShape` and `errorShape` all tell you the symbol is "an object
with some fields" -- which is already what a type says -- while saying
nothing about what the value is for or who owns it. The rule forces the
name to carry the domain instead.
Violations fixed
----------------
689 violations across 109 files at baseline (verified by re-running the
audit against the pre-change tree with the rule set to "error").
Fix pattern
-----------
Rename for the domain role, not the structure:
-type FieldShape = 'list' | 'map' | 'whole'
-const FIELD_SHAPES = { ... } satisfies Record<keyof Observation, FieldShape>
+type FieldEncoding = 'list' | 'map' | 'whole'
+const FIELD_ENCODINGS = { ... } satisfies Record<keyof Observation, FieldEncoding>
-function assertGitPushTargetShape(target: unknown): void
+function assertValidGitPushTarget(target: unknown): void
-function describeReadDirPathShape(p: string): ReadDirPathKind
+function classifyReadDirPath(p: string): ReadDirPathKind
Predicates became statements about the value (`isDeltaShapedProviderFrameKind`
-> `isDeltaProviderFrameKind`, `isDeleteShapedDiscardEntry` ->
`discardDeletesEntryFile`, `isSkillsCliAgentKeyShaped` ->
`isUsableSkillsCliAgentKey`). Type aliases dropped the suffix where the
remaining name was already unambiguous (`GhGraphqlErrorShape` ->
`GhGraphqlError`).
No wire-visible name was renamed: no IPC or RPC channel, stream opcode,
request/response param, persisted field, or i18n key. The `--shape=symlink|copy`
CLI flag read by .github/workflows/skill-update-roundtrip.yml is unchanged --
only the local variable holding it was renamed.
Exemptions
----------
They are file-scoped entries in config/oxlint-anti-slop.json, not inline
`oxlint-disable` comments. An inline directive naming an anti-slop rule reads
back as an UNUSED directive under the root lint scan, which does not load this
plugin -- the changed-code quality gate counts that warning, so the comment form
cannot be used for a rule that lives only in this config.
* src/renderer/src/components/browser-pane/annotate/**:
in the screenshot annotator a "shape" is the drawn geometry -- pen, arrow,
rect, ellipse, highlight. That is a genuine domain noun, and it pervades
every symbol in the module.
* repo-icon.tsx, repo-header-project-actions.tsx, mobile MobileRepoIcon.tsx:
lucide exports the icon component as `Shapes`. The name is theirs, and the
matching REPO_LUCIDE_ICONS key is the persisted icon name shared with the
desktop picker -- renaming it would orphan saved repo icons.
* src/shared/onboarding-state-types.ts, src/shared/constants.ts:
`shapedSidebar` is a persisted onboarding-checklist field and a telemetry
enum member; renaming it would orphan saved state.
* src/shared/rpc-contract/rpc-send-params.ts: matching zod's own literal `shape`
property is what selects the ZodObject branch of the conditional type.
No exemption was added merely to avoid a rename. Eight symbols initially
suppressed as "a cross-module refactor outside this change" were proven to have
zero non-TypeScript references repo-wide and renamed instead.
Zod's `ZodRawShape` needed no exemption at all: `Readonly<Record<string,
z.ZodType>>` is its definition, so repo-update-params.ts and
ui-update-value-tolerance-params.ts spell it out instead. Likewise
telemetry-event-classification.ts now reads `.shape` through an `in` narrowing,
which also retires two pre-existing type assertions; three more assertions the
rename had dragged onto changed lines (two `JSON.parse` sites, one node:sqlite
row read) became annotations and an explicit row mapping.
Verified
--------
* Audit reports zero violations; confirmed the rule genuinely fires by
planting a probe violation.
* node config/scripts/run-typecheck-projects-in-parallel.mjs exits 0.
* Vitest over src/shared, src/main/github/project-view, the annotate module,
the repo-icon components and the Chromium SameSite electron spec: all green.
* All 66 removed "shape" identifiers grepped repo-wide across every file type;
none survive.
* node config/scripts/generate-rpc-params-catalog.mjs --check exits 0.
* node --check on every changed .mjs; oxfmt clean on all changed files.
* `pnpm run check:code-quality:changed` reports 0 findings.
Not machine-verified: the 3 mobile/ files (its Vitest run cannot resolve
`expo/tsconfig.base.json` in this worktree), and the WSL- and Playwright-gated
specs. All are rename- or comment-only hunks, read in full.
55 lines
2.1 KiB
TypeScript
55 lines
2.1 KiB
TypeScript
import type { GitPushTarget } from './worktree/types'
|
|
|
|
const SAFE_REMOTE_NAME_SEGMENT = /^[A-Za-z0-9][A-Za-z0-9._-]*$/
|
|
const GITHUB_CLONE_URL = /^https:\/\/github\.com\/[A-Za-z0-9_.-]+\/[A-Za-z0-9_.-]+\.git$/
|
|
const GITHUB_SSH_URL = /^git@github\.com:[A-Za-z0-9_.-]+\/[A-Za-z0-9_.-]+\.git$/
|
|
|
|
function assertString(value: unknown, name: string): asserts value is string {
|
|
if (typeof value !== 'string') {
|
|
throw new Error(`Invalid PR push target ${name}.`)
|
|
}
|
|
}
|
|
|
|
export function isSafeGitRemoteName(remoteName: string): boolean {
|
|
if (remoteName.length === 0 || remoteName.length > 100) {
|
|
return false
|
|
}
|
|
return remoteName.split('/').every((segment) => {
|
|
// Git accepts slash-separated remote names; each segment still needs to be
|
|
// a concrete name so persisted push targets cannot smuggle path traversal.
|
|
return (
|
|
segment !== '' &&
|
|
segment !== '.' &&
|
|
segment !== '..' &&
|
|
SAFE_REMOTE_NAME_SEGMENT.test(segment)
|
|
)
|
|
})
|
|
}
|
|
|
|
// Why: the relay allows a fork remote to be added via git.exec, so the exec
|
|
// validator needs the same URL rule the pushTarget-carrying RPCs already apply.
|
|
export function isSafePushTargetRemoteUrl(remoteUrl: string): boolean {
|
|
return GITHUB_CLONE_URL.test(remoteUrl) || GITHUB_SSH_URL.test(remoteUrl)
|
|
}
|
|
|
|
export function assertValidGitPushTarget(target: unknown): asserts target is GitPushTarget {
|
|
if (typeof target !== 'object' || target === null) {
|
|
throw new Error('Invalid PR push target.')
|
|
}
|
|
const candidate = target as Record<string, unknown>
|
|
assertString(candidate.remoteName, 'remote name')
|
|
assertString(candidate.branchName, 'branch name')
|
|
if (!isSafeGitRemoteName(candidate.remoteName)) {
|
|
throw new Error(`Invalid git remote name: ${candidate.remoteName}`)
|
|
}
|
|
if (!candidate.branchName || candidate.branchName.startsWith('-')) {
|
|
throw new Error(`Invalid git branch name: ${candidate.branchName}`)
|
|
}
|
|
if (candidate.remoteUrl !== undefined) {
|
|
assertString(candidate.remoteUrl, 'remote URL')
|
|
if (!isSafePushTargetRemoteUrl(candidate.remoteUrl)) {
|
|
throw new Error('Invalid PR push target remote URL.')
|
|
}
|
|
}
|
|
}
|